openhands-automation

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is mostly aligned with its stated OpenHands automation purpose and uses official OpenHands endpoints, but it materially expands trust by allowing arbitrary plugin sources, cloning repos that auto-load skills, and triggering autonomous runs from untrusted external events. The main concern is transitive instruction/plugin loading and prompt-injection risk, not obvious credential theft or fake endpoint routing.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
May 8, 2026, 04:32 AM
Package URL
pkg:socket/skills-sh/openhands%2Fskills%2Fopenhands-automation%2F@51724051c3fb0434c60c2c0e5fa09dd86ed242d3